Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Notepad++ server hacked: attack via updates
- The KSeF system: Is our data safe?
- When can an online store require you to create an account?
- TrickMo impersonates AdGuard: risk of online banking credential theft
- CBZC dismantles a criminal gang laundering money from numerous scams
- Who is El Mencho, and how did his cartel operate?
- Former ABW and SKW chiefs face charges of failing to fulfill their duties in the Pegasus investigation
- Poland’s first AI voice-cloning theft case goes to court
- Is a courier company the data controller for personal data contained in shipped documents?
- iPhone and iPad approved to handle classified NATO information
- Detecting and preventing distillation attacks
- Threat attribution framework. How TrendAI applies structure over speculation
- Top 7 dark web markets in 2026: What gets sold
- Total ransomware payments stagnate for second consecutive year, while attacks escalate
- Texas sues TP-Link over Chinese hacking risks, user deception
- PayPal discloses data breach that exposed user info for 6 months
- Spanish police say they have arrested hacker who booked luxury hotel rooms for just one cent
- Trenchant exec who sold his employer's zero-day exploits to Russian buyer sentenced to 7 years in prison
- Meta’s AI sending ‘junk’ tips to DoJ, US child abuse investigators say
- Greek court sentences Predator spyware gang
For the more technical
- Why is hacking web applications so easy?
- AI-augmented threat actor accesses FortiGate devices at scale
- Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
- AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks
- Four vulnerabilities expose a massive security blind spot in IDE extensions
- Developer-targeting campaign using malicious Next.js repositories
- Apache ActiveMQ exploit leads to LockBit ransomware
- SURXRAT: From ArsinkRAT roots to LLM module downloads signaling capability expansion
- Large-scale online deanonymization with LLMs
- How Predator spyware defeats iOS recording indicators
- Malicious OpenClaw skills used to distribute Atomic MacOS Stealer
- Fake Huorong security site infects users with ValleyRAT
- Fake Zoom and Google Meet scams install Teramind: A technical deep dive
- Free games, costly consequences
- Unmasking Agent Tesla: A deep dive into a multi-stage campaign
- GrayCharlie hijacks law firm sites in suspected supply-chain attack
- How Tycoon 2FA is rewriting the rules of identity theft: Not just a phishing kit – a business model
- Chronology of MuddyWater APT attacks targeting the Middle East
- Exposing the undercurrent: Disrupting the GRIDTIDE global cyber espionage campaign
- New Dohdoor malware campaign targets education and health care
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments